vulnerability

Red Hat: CVE-2025-61915: CUPS: Local denial-of-service via cupsd.conf update and related issues (Multiple Advisories)

Severity
4
CVSS
(AV:L/AC:L/Au:M/C:N/I:N/A:C)
Published
Nov 28, 2025
Added
Jan 15, 2026
Modified
Jan 15, 2026

Description

A flaw was found in cups. A user in group defined by SystemGroup directive in /etc/cups/cups-files.conf can use the cups web ui to change the config
and insert a malicious line. Then the cupsd process which runs as root will parse the new config and cause an out-of-bound write.

Solutions

redhat-upgrade-cupsredhat-upgrade-cups-clientredhat-upgrade-cups-client-debuginforedhat-upgrade-cups-debuginforedhat-upgrade-cups-debugsourceredhat-upgrade-cups-develredhat-upgrade-cups-filesystemredhat-upgrade-cups-ipptoolredhat-upgrade-cups-ipptool-debuginforedhat-upgrade-cups-libsredhat-upgrade-cups-libs-debuginforedhat-upgrade-cups-lpdredhat-upgrade-cups-lpd-debuginforedhat-upgrade-cups-printerappredhat-upgrade-cups-printerapp-debuginfo
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.